Live data from Hacker News

Apple enabling client-side CSAM scanning on iPhone tomorrow

twitter.com

11–20 of 757 posts

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#12
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

Apple beat government spying in the past so I don't see why they can't again.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#13

So if I understand correctly, they want to scan all your photos, stored on your private phone, that you paid for, and they want to check if any of the hashes are the same as hashes of child porn? So... all your hashes will be uploaded to the cloud? How do you prevent them from scanning other stuff (memes, leaked documents, trump-fights-cnn-gif,... to profile the users)? Or will a huge hash database of child porn hash…

>So... all your hashes will be uploaded to the cloud? That isn't how I interpret "client-side". The privacy implications are far more subtle.

It's still really, really bad.

It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China.

This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism.

Perceptual hashes like what Apple is using are already used in WeChat to detect memes that critique the CCP.

What happens on local end user devices must be off limits. It is unacceptable that Apple is actively implementing machine learning systems that surveil and snitch on local content.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#14
post #11
post #9

I'm assuming android/google must do this already?

Android uploads everything to the cloud and it gets scanned there. But maybe in the future the Tensor SoC can rat you out client-side.

No, it doesn't if you choose to keep it local.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#16
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

It’s not trying to close Pandora’s box. It’s liability limitation. They’re effectively saying that if you want to distribute CP don’t do it on an iPhone.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#17
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

I don't understand this argument at all. Look at the Clipper Chip debacle in the 90s. It was technically feasible and the government very much wanted to do it. And the reason they didn't is push back from the public, saying this is a bad idea that can easily be misused, even if it does make some law enforcement things easier. I don't see how this is any different.

Sacrificing the privacy of the many to help catch a relatively small amount of (admittedly some of the worst possible) criminals, while simultaneously enabling yet more effective surveillance and oppression by those inclined governments (of which there are plenty) is a pretty terrible idea.

Eliminating the 4th amendment or mandating clear walls sure would make the cops' job easier. But no one thinks that's even a remotely good idea.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#18
post #6

I understand the hesitation here, but fundamentally this is like trying to close pandoras box. If something is technically possible to do AND governments demand it be done, it will be done. If not by Apple, by someone else. Rather than complain about it, I am interested in what alternative solutions exist, or how concerns regarding privacy and abuse of this system could be mitigated.

No, we can complain about it, and we can win. Remember when the government tried to ban encryption in early 1990s?

Remember SOPA that the internet killed?

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#19
post #13

Earlier quoted context omitted.

>So... all your hashes will be uploaded to the cloud? That isn't how I interpret "client-side". The privacy implications are far more subtle.

It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…

I agree with you 100% — the only solution I’ve found workable is limiting my use of the technology itself as much as possible.

Re: Apple enabling client-side CSAM scanning on iPhone tomorrow

#20
post #13

Earlier quoted context omitted.

It's still really, really bad. It always starts with child porn, and in a few years the offline Notes app will be phoning home if you write speech criticising the government in China. This technology inevitably leads to the sueveillance, suppression and murder of activists and journalists. It always starts with protecting the kids or terrorism. Perceptual hashes like what Apple is using are already used in WeChat to…

I agree with you 100% — the only solution I’ve found workable is limiting my use of the technology itself as much as possible.

Or regulation saying that this is illegal, because it invades users privacy too much.
Post reply on HN